Cyber overview
Cyber threat actor

Hafnium

PRC state-sponsored · active since 2017

Author of the 2021 ProxyLogon Microsoft Exchange zero-day campaign that compromised 30,000+ servers worldwide.

Aliases
Silk Typhoon
Primary targets
Defense contractors Higher education Law firms Think tanks Infectious disease researchers

MITRE ATT&CK techniques

3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

TacticTechniqueProcedureTargetsCitation
Initial AccessT1190
Exploit Public-Facing Application (ProxyLogon)
Mass-exploitation of the ProxyLogon Exchange Server zero-day chain before patches were available.
30,000+ Exchange servers globallyMicrosoft ProxyLogon
PersistenceT1505.003
Server Software Component: Web Shell (China Chopper)
Dropped China Chopper variant web shells on compromised Exchange servers for persistence.
-Microsoft ProxyLogon
CollectionT1114.002
Remote Email Collection
Full mailbox exports of targeted users at defense, law, education, and infectious-disease research orgs.
-Microsoft ProxyLogon

Curated incidents

  1. 2021-03-02·Cross-sector·Global
    Hafnium ProxyLogon zero-days compromise 30,000+ Exchange servers

    Mass-exploitation of CVE-2021-26855 chain before patches were available.